Skip to content

EXP-001 provider-free entitlement and model identity - #18

Open
sneakocom wants to merge 1 commit into
mainfrom
exp-001-entitlement-model-identity
Open

sneakocom wants to merge 1 commit into
mainfrom
exp-001-entitlement-model-identity

Conversation

@sneakocom

@sneakocom sneakocom commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Summary

  • define account entitlement as exact credential, organization, project, model,
    and Responses API permission at probe time
  • catalogue official non-inference OpenAI model/project metadata surfaces and
    cap positive evidence at UNVERIFIED because the documentation does not make
    discovery invocation-equivalent
  • freeze a public-safe documentation snapshot and require an exact documented
    immutable provider model identity; current gpt-5.6-sol evidence has none
  • add dormant schemas, fail-closed validators, synthetic fixtures, launch-order
    checks, program-ledger controls, and public evidence receipts
  • dogfood actual Affected Verification, Decision Evidence, Visible Value, and
    Agent Trajectory Profiler implementations

Provider-free safety statement

This PR is provider-free only.

  • provider/model subjects: 0
  • authenticated provider probes: 0
  • model inference requests: 0
  • authorization consumptions: 0
  • experiment runs: 0
  • experiment results: 0
  • result envelopes: 0
  • EXP-001 lifecycle: PLANNED

No private LIVE_PROVIDER_RUN label or mapping was read or changed. No API key,
bearer header, credential value, provider session, or authenticated provider
request was used.

Readiness conclusions

Account entitlement cannot currently be proven under the documented semantics
without inference. OpenAI documents authenticated, non-inference GET metadata
for model discovery, project status, project credential binding, model policy,
and rate limits. A future separately authorized composite probe can collect
account/project-specific evidence and establish decisive negative states, but
current official documentation does not state that a positive response from
any one surface or their combination guarantees invocation through
/v1/responses. Positive metadata therefore remains UNVERIFIED, never
ENTITLED.

An immutable/datable model identity is not currently obtainable for the
preregistered model. The public model page identifies gpt-5.6-sol, says
gpt-5.6 routes to it, and repeats the same undated identifier in its snapshot
table. It does not expose a distinct immutable dated snapshot. The Responses
schema exposes the returned model field but no documented provider revision
or fingerprint. The strict policy therefore blocks aliases and undocumented
mutable identifiers.

Remaining blockers

  1. Current official metadata semantics cannot classify positive account-
    specific non-inference evidence as ENTITLED.
  2. No distinct provider-documented immutable/datable gpt-5.6-sol identity is
    available for a versioned preregistration amendment.
  3. The existing live authorization remains unconsumed and still requires
    separate provider/model execution authority after every provider-free gate
    can pass.

Verification

  • 49/49 selected unit tests passed (32 program + 17 readiness)
  • program registry: 21 repositories, 18 concepts, 2 experiments
  • generated dashboard check passed
  • two opsle.value-receipt.v1 validations passed
  • readiness qualification reproduced byte-for-byte as BLOCKED
  • ruff focused checks passed
  • actionlint passed
  • git diff --check passed
  • gitleaks scanned 9b9b5ca..0309054: no leaks

Actual Affected Verification 0.1.0 produced plan
sha256:649b47f0ac224c347d41c0b28b02131a329802961532df4bc6d9e6273001433d
with SUFFICIENT_BROADENED, no impact uncertainty, 49 of 170 catalogued test
executions selected, and 121 skipped with explicit reasons. Full discovery and
the offline harness remain policy-required PR CI checks and were not replaced
by the planner.

Review boundary

Please review only. Do not merge this PR during the requested independent
review, launch EXP-001, consume authorization, or send an authenticated provider
probe.

@sneakocom
sneakocom force-pushed the exp-001-entitlement-model-identity branch from 07b3bf9 to 0309054 Compare August 31, 2026 02:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant